Description
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/497
Related Vulnerabilities
CVE-2020-2150 Vulnerability in maven package org.jenkins-ci.plugins:quality-gates
CVE-2016-6793 Vulnerability in maven package org.apache.wicket:wicket-util
CVE-2017-16031 Vulnerability in npm package socket.io
CVE-2019-1003096 Vulnerability in maven package org.jenkins-ci.plugins:testfairy
CVE-2020-7766 Vulnerability in maven package org.webjars.npm:json-ptr